Who this is for, and who it is not
AutoPQC suits organisations with a large, mixed, poorly documented cryptographic estate. If that is not you, this page says so before you spend a meeting on it
On this page — 6 sections
A cryptographic inventory platform is worth paying for under a narrow set of conditions. This page describes those conditions, then describes the organisations that should not buy AutoPQC. The second list is longer than most vendors would print. We would rather lose a bad-fit deal at the reading stage than at month four.
The conditions that make this worthwhile
Value comes from scale, heterogeneity and accountability. Remove any one of the three and a spreadsheet maintained by one careful engineer will beat us.
- Scale. Enough systems that nobody holds the full picture — typically hundreds of services or more, across more than one platform generation.
- Heterogeneity. A mix of languages, runtimes, appliances and acquired estates. Uniform estates are easy to audit by hand.
- Age. Cryptography deployed by people who have since left, under decisions nobody documented.
- Accountability. Somebody has to answer a regulator, a board, a customer questionnaire or an internal audit finding about post-quantum readiness, on a date.
- Long data lifetime. Data intercepted today still matters in ten years, which is what makes harvest-now-decrypt-later a present-tense problem rather than a future one. See Harvest now, decrypt later.
The last point is the one that separates urgency from housekeeping. If nothing you transmit retains value beyond a few months, your migration deadline is set purely by regulation, and regulation moves slower than this platform is priced for.
There is a practical test for scale. Ask two senior engineers, independently, to name every place TLS terminates in your estate. If their answers agree, you do not have an inventory problem. If they differ by more than a handful of systems, and neither is confident, you have the problem this platform exists for.
Sectors we are built around
| Sector | The pressure | What discovery usually surfaces first |
|---|---|---|
| Banking and capital markets | DORA operational-resilience obligations, long-lived contractual data | TLS termination sprawl, payment HSM key hierarchies, ageing signing infrastructure |
| Insurance | Policy and claims data with multi-decade retention | Document-signing chains, partner file transfer, archived encryption at rest |
| Telecommunications | Bulk transit that is cheap to record and store | Subscriber authentication, inter-operator links, network element configuration |
| Healthcare and life sciences | Patient records that stay sensitive for a lifetime | Device and gateway TLS, research data transfer, legacy integration engines |
| Government and defence suppliers | CNSA 2.0 expectations in the supply chain | Code signing, firmware trust anchors, cross-domain transfer |
| Enterprise SaaS | Customer questionnaires and contractual crypto commitments | Dependency-level cryptography, tenant key handling, third-party integrations |
Sector-specific framing lives on /solutions. Regulatory detail is in the standards category, including DORA and financial-sector obligations, CNSA 2.0 and the federal timeline and The Indian regulatory picture.
The roles that get value
- CISO or head of security architecture
- Needs a defensible position on post-quantum readiness and a programme they can resource and stage.
- Cryptography or PKI lead
- Needs the asset-level truth, including the systems they suspect exist but cannot prove.
- Platform and infrastructure engineering
- Needs to know which of their services are affected, and what the change costs in latency before agreeing to it.
- Internal audit and compliance
- Needs dated evidence with provenance rather than an assurance that work is under way.
- Programme or transformation lead
- Needs a sequenced backlog with dependencies, not a list of vulnerabilities.
Who should not buy AutoPQC
Read this section as written. Each item below describes a real enquiry pattern we redirect rather than sell to.
- Individuals and small teams. If you are one person auditing one application, you do not need a platform. The published method at /methodology and the Lexicon are free, and they are enough to do this work by hand.
- Blockchain, wallet and DeFi projects. Our detectors, asset model and scoring are built for enterprise infrastructure — TLS, PKI, HSMs, code signing, data at rest. We do not audit smart contracts, we do not score wallet addresses, and we do not analyse on-chain signature exposure. That is a different product from a different vendor.
- Anyone wanting a penetration test. We do not attack your systems. If your requirement is adversarial testing, buy adversarial testing.
- Anyone wanting a code security audit. We look for cryptographic usage, not injection flaws, authorisation bugs or logic errors. Our detectors will walk straight past a serious non-cryptographic vulnerability.
- Anyone wanting us to make the change. We do not have hands on your production estate. We produce the plan, the priority and the performance evidence. Your teams, or an integrator you appoint, do the work.
- Anyone wanting a certification. A Posture Attestation records what we observed and scored on a given date. It is not accreditation, and no regulator treats it as such. See What to hand an auditor for what it does and does not carry.
- Organisations that cannot grant read access. If policy prevents any read-only access to repositories, configuration or endpoint metadata, discovery cannot run. Interview-based inventory work is a consulting engagement, and it is not what this platform is.
- Estates that are already uniform and documented. If you have one TLS library, one key hierarchy and a current inventory, you have already done the expensive part. Use FIPS 203, 204 and 205, mapped to output and go straight to sequencing.
Out of scope
We do not sell or operate post-quantum cryptographic libraries, key-management appliances, quantum key distribution, or random-number hardware. We do not remediate on your behalf, we do not manage your PKI, and we do not offer a managed security service. AutoPQC is an assessment and decision-support platform. Anyone telling you a single product both discovers and fixes an enterprise cryptographic estate is selling you something we do not have.
Signals you are too early
Timing is a real disqualifier and it is easy to misjudge. If more than one of the following is true, the honest recommendation is to come back later.
- 01No named owner for the post-quantum question. Without an owner, the report gets read and nothing happens.
- 02No agreed estate boundary. If nobody can say which business units are in scope, scoping alone will consume the engagement.
- 03No change-control capacity for the next two quarters. A prioritised backlog you cannot act on decays.
- 04An unresolved asset-inventory problem at a more basic level. If you do not know what servers you run, cryptographic discovery is the wrong first project.
- 05A pending platform migration that will invalidate the findings. Assess the estate you will have, not the one you are dismantling.
A cheaper first step
The readiness check and migration window arithmetic will tell you whether your deadline is genuinely close, using your own numbers for data lifetime and migration duration. Both are free and neither requires access to your environment.
If you are on the boundary
Borderline cases are common: a mid-sized organisation with one very old estate, or a large one where only a single regulated business unit has a deadline. In those cases a Baseline Assessment scoped to a single business unit is usually the right shape. It produces a real inventory over a bounded surface, and it gives you a defensible answer about whether the rest of the estate justifies a Deep Migration Engagement.
The other common borderline case is an organisation whose deadline is real but whose ownership is not yet settled. Cryptographic inventory work cuts across networking, application engineering, PKI and audit, and the findings arrive as questions for teams that did not commission them. Where no single person can convene those groups, the report will be accurate and inert. If that describes you, the useful first move is naming the owner rather than buying the assessment.
One thing we will not do is scope an engagement to flatter a business case. If your estate is smaller or better documented than your deadline implies, we will say so in the scoping call and quote for less work than you asked about, or for none.
Tell us the awkward version of your situation rather than the tidy one. We would rather scope down, or decline, than run an engagement that produces a report nobody can use.
Describe the estate, the deadline and who owns the question. If AutoPQC is the wrong tool, we will say so and point you at the part of the published method you can use without us.Tell us your situation